An Internet of Things device security access control method based on the idea of segmentation

By adopting a secure access control method based on segmentation ideas in the Internet of Things environment, combining the LBlock algorithm and key segmentation ideas, the problems of information security and access control flexibility of IoT devices are solved, and a higher level of information security protection is achieved.

CN119254518BActive Publication Date: 2025-06-17NEIJIANG NORMAL UNIV +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411451188.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-17
Publication Date
2025-06-17
Estimated Expiration
2044-10-17

AI Technical Summary

Technical Problem

It is difficult to implement role-based flexible access control policies and hardware protection measures of traditional networks in the Internet of Things environment, resulting in insufficient flexibility in information security and access control.

Method used

The secure access control method of IoT devices based on segmentation ideas is adopted, combined with the LBlock lightweight packet cryptography algorithm and key segmentation idea, and the information encryption, signature authentication and integrity verification are realized through information transmission between the proxy server and the client.

Benefits of technology

It strengthens the confidentiality, integrity and security of information, improves the flexibility of access control and the system's information security assurance mechanism, and is suitable for high security and lightweight application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119254518B_ABST
    Figure CN119254518B_ABST
Patent Text Reader

Abstract

The present invention discloses an Internet of Things device security access control method based on the segmentation idea, which is applied to the field of communication technology. Aiming at the flexible access control strategy based on roles and hardware protection measures in traditional networks, they are not applicable to the data security and access control of the Internet of Things mainly composed of lightweight devices. Through initial settings or the operations of proxy servers, the present invention sets up the LBlock lightweight block cipher algorithm, and uses the segmentation idea to provide a higher level of security protection for Internet of Things devices. Especially in application scenarios that require high security and light weight, the information can be encrypted and not tampered with, ensuring the confidentiality and integrity of the information and ensuring information security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communication technologies, and particularly relates to an Internet of Things (IoT) communication security technology. Background Art

[0002] With the wide application of big data and the Internet of Things, the scale and complexity of data have been continuously increasing, and data security and access control have become key issues. In the IoT environment, access control and identity authentication are key technologies for ensuring control security. By implementing strict access control policies, the access rights to IoT devices and systems can be restricted, preventing unauthorized users or devices from operating on critical resources. At the same time, by adopting strong cryptographic algorithms and secure identity authentication mechanisms, the authenticity and credibility of device and user identities can be ensured, preventing identity impersonation and forgery.

[0003] The current IoT security access control technology faces challenges in implementing flexible role-based access control policies and hardware protection measures in traditional networks. Although the security of IoT transmission and stored information can be improved by setting access control policies to prohibit access to unauthorized resources, the implementation of such policies still poses challenges. The adoption of secure hardware protection mechanisms can resist reverse analysis and unauthorized access behaviors, which is one of the effective security control measures for the IoT. Summary of the Invention

[0004] To solve the above technical problems, the present invention proposes an IoT device secure access control method based on the segmentation idea. Mainly through initial settings or operations of a proxy server, an LBlock lightweight block cipher algorithm is set. Using the segmentation idea provides a higher level of security protection for IoT devices, especially in application scenarios that require high security and lightweight, enabling information to be encrypted and not tampered with, ensuring the confidentiality and integrity of information, and ensuring information security.

[0005] The technical solution adopted by the present invention is: an IoT device secure access control method based on the segmentation idea, and the application scenarios include: a client, a proxy server, and a user; denote the client as o, the proxy server as d, and the user as s; the access control method includes the following steps:

[0006] S1. The proxy server d generates a subscription instruction according to the instruction sent by the user s, and sends the subscription instruction to the client o by using an improved segmentation method;

[0007] S2. The client o receives the information from the proxy server d, processes it, and confirms the integrity of the information;

[0008] S3. The client o publishes subscription data to the proxy server d by using the improved segmentation method according to the content of the subscription instruction;

[0009] After the proxy server d receives the information of the client o, it will send the information judged by information security and information source reliability to the user s.

[0010] Advantages of the present invention: Compared with previous inventions, the present invention introduces restricted elements such as blacklists of users and devices, and elements such as sensitive strings and data, further strengthens the functions of information encryption, signature authentication, and integrity verification, and at the same time introduces the security levels of users and devices to strengthen the access control level, thereby strengthening the information security guarantee mechanism of the system, and combining the LBlock lightweight block cipher algorithm and the key splitting idea. Description of the Drawings

[0011] Figure 1 It is a framework diagram of the proxy server related to the present invention.

[0012] Figure 2 It is a specific flowchart of steps 2-step 3 of the specific embodiment of the present invention.

[0013] Figure 3 It is a specific flowchart of steps 4-step 5 of the specific embodiment of the present invention. Detailed Embodiments

[0014] The object of the present invention is: For the link between the proxy server and the device in the user-proxy server-client Internet of Things environment framework, a security access control method for Internet of Things devices combining the LBlock lightweight block cipher algorithm and the key splitting idea is given. This method aims to improve the security and access control flexibility of Internet of Things devices by introducing the lightweight block cipher algorithm and the splitting idea, aiming at the characteristics that most Internet of Things devices are lightweight and have limited computing power, and realizes fast access between the proxy server and the device, without specifically involving the security access control method between the user and the proxy server.

[0015] The LBlock lightweight block cipher algorithm is adopted to flexibly encrypt data and improve the security of the system. The key splitting idea: is realized through physical separation, logical separation or a combination of both. In this way, even if some keys are leaked, the attacker cannot use these keys alone to decrypt the data, because other parts of the keys are also required. In the Internet of Things environment, the security access control method designed by the present invention can be applied to aspects such as device authentication and data access control. By combining the authentication and access control strategies of Internet of Things devices, it is ensured that only authorized devices can access sensitive data or perform critical operations.

[0016] In order to achieve the above object, the technical solution of the present invention is: A security access control method for Internet of Things devices based on the splitting idea, including the following main steps:

[0017] Step 1. The proxy server d subscribes to instructions from the client o;

[0018] Step 2. The client o receives the information from the proxy server d and processes it;

[0019] Step 3. The client o publishes subscription data according to the content of the subscription instruction;

[0020] Step 4. After receiving the information from the client o, the proxy server d further determines the information security and the reliability of the information source.

[0021] To facilitate the understanding of the technical content of the present invention by those skilled in the art, the content of the present invention will be further explained below with reference to the accompanying drawings.

[0022] The LBlock lightweight block cipher algorithm involved in the present invention refers to the literature of Wu Wenling and Zhang Lei: WU W L, ZHANG L. LBlock: A lightweight block cipher [C] / / International Conference on Applied Cryptography and Network Security, 2011: 327-344.; The Hughes key exchange algorithm and the splitting idea refer to the reference: Shilei (USA) wrote, translated by Wu Shizhong et al. Applied Cryptography: Protocols, Algorithms and C Source Programs [M]. Beijing: China Machine Press, 2014.1.

[0023] 1. LBlock Algorithm

[0024] The LBlock algorithm is a lightweight block encryption algorithm proposed by Wu Wenling and Zhang Lei at ACNS 2011. Its block length is 64 bits and the key length is 80 bits. It is a 32-round iterative block algorithm, adopting the Feistel algorithm structure. The encryption algorithm and the decryption algorithm are inverse to each other, and the order of the round keys used is opposite. Secondly, an original design is made for the key expansion algorithm, adopting the Feistel structure and the SPN structure.

[0025] 2. Hughes Key Exchange Algorithm

[0026] The Hughes key exchange algorithm is a variant of the Diffie-Hellman key exchange algorithm, allowing Alice to generate a key and send it to Bob. Let p be a large prime number and g be a primitive root of p. p and g are used as public global elements.

[0027] (1) Alice selects a large random integer x and generates k = g x mod p;

[0028] (2) Bob selects a large random integer y and sends it to Alice: Y = g y mod p;

[0029] (3) Alice sends to Bob: X = Y x mod p;

[0030] (4) Bob calculates z = y -1 , k' = X z mod p

[0031] After calculation, k = k', thus realizing the key sharing between Alice and Bob.

[0032] In the present invention, the Hughes key exchange algorithm is used to realize the key sharing between the proxy server d and the client o, and two shared keys K-do1 and K-do2 are generated and alternately used as the encryption and decryption keys for the LBlock algorithm and the shared key for data segmentation.

[0033] 3 Splitting idea

[0034] Splitting idea: A splits the message M and distributes it to B and C as follows:

[0035] (1) A generates a random bit string R, which is as long as the message M;

[0036] (2) A uses R to XOR M to get S: M ⊕ R = S;

[0037] (3) A gives R to B and S to C;

[0038] (4) B and C together XOR the messages they received to reconstruct the message: R ⊕ S = M.

[0039] In the present invention, in order to adapt to the characteristics that most clients belong to lightweight devices, this method is improved to realize the information transmission between the proxy server d and the client o. The improvement method is as follows:

[0040] Improved splitting idea: A splits the message M||cert(J) with the certificate cert(J). A has the certificate cert(J), and A and B share the shared key K. The method is as follows:

[0041] (1) A generates a random bit string R, which is as long as the message M||cert(J) and K; if the three are not of the same length, the method of padding several 0s in front of the shorter one or two is adopted to make the three numbers of the same length;

[0042] (2) A uses R to XOR M||cert(J) to get S: (M||cert(J)) ⊕ R = S;

[0043] (3) Party A performs an exclusive OR operation on R and K to obtain W: R⊕K = W. Party A gives both S and W to Party B;

[0044] (4) After receiving S and W, Party B can reconstruct this message by performing an exclusive OR operation on them together with the shared key:

[0045] S⊕W⊕K = ((M||cert(J))⊕R)⊕(R⊕K)⊕K = M||cert(J)

[0046] By keeping the random number R secret through K, it can play a role in protecting the confidentiality of information transmission. At the same time, it verifies Party A's certificate to confirm that the information comes from Party A.

[0047] In the access control process for lightweight devices of the present invention, this improved splitting idea encryption is used. As an encryption method, by splitting information into multiple parts, each part can be encrypted using different encryption keys, increasing the difficulty for attackers to crack the information. This encryption method not only improves the security of information transmission but also enhances the security of information. Through splitting idea encryption, even if part of the information is intercepted, it is difficult for attackers to infer the content of the overall information from the partial information, thus protecting the integrity and privacy of the information. In addition, in the present invention, the splitting idea encryption is combined with the symmetric encryption algorithm LBlock algorithm to further improve the security of information. Such an encryption method reduces the security risk on the key to a certain extent and enhances the concealment of information transmission; after using this improved splitting idea encryption, its computational complexity only increases by two exclusive OR operations. Since the exclusive OR operation only involves the comparison of two input values, its computational complexity is relatively low and has little impact on the processing efficiency and resource occupancy of lightweight devices; compared with the access control process of lightweight devices that do not use splitting idea encryption, it sacrifices a small amount of processing efficiency and resource occupancy in exchange for higher security in the access control process.

[0048] According to the Classification Criteria for Security Protection Levels of Computer Information Systems in China (GB 17859-1999), their security levels are evaluated respectively, and at the same time, the relevant security elements involved are initialized and evaluated and set respectively. The specific relevant concepts and notations are as follows:

[0049] Let the security level of client o be denoted as: T(o); the set of users restricted from access by o be denoted as: o-s-limit() (user blacklist set); the set of instruction keyword strings not allowed to be subscribed by o be denoted as: o-s-ins-limit() (sensitive string blacklist set), and apply for user certificate cert(o) from proxy server d.

[0050] Let the security level of user s be denoted as: T(s), the set of devices o restricted by s for access be denoted as: s - o - limit() (device blacklist set), the set of published data keywords not allowed to be received by s be denoted as: s - o - ins - limit(), and apply for user certificate cert(s) from proxy server d.

[0051] The certificate of the proxy server is: cert(d).

[0052] For simplicity, in the present invention, E and D are respectively used to denote the corresponding encryption and decryption algorithms; the shared keys between proxy server d and client o are denoted as K - do1 and K - do2.

[0053] When communicating parties transmit information, it is set that: t represents the timestamp when each party sends or receives information, and it is set that the data interval received by the sender and the receiver does not exceed Δt, that is, as long as the time interval is within Δt, and if it exceeds, it is considered that the data transmission fails or a replay attack is suffered. The setting of Δt depends on factors such as the transmission delay, propagation delay, processing delay, and queuing delay of specific transceiver devices. Taking the transmission of data from the proxy server to the client as an example, if the transmitted file size is 1MB and the transmission rate is 1Mbps, then the transmission delay = (1MB * 8) / 1Mbps = 8ms; assuming that the transmission path length of the data is 1000 kilometers and the propagation rate is 2 times the speed of light (about 6 * 10^8 meters per second), then the propagation delay = 1000000 meters / 6 * 10^8 meters per second = 1.67ms. Assuming that the processing delay and queuing delay are each 2ms, then the delay of the proxy server transmitting data to the client is 8 + 1.67 + 2 + 2 = 13.67ms; further analyzing the possible delay of the client transmitting data to the proxy server, assuming it is 12.67ms, then the maximum value of the two - aspect delays, 13.67ms, is taken as Δt.

[0054] The present invention will be further described below in conjunction with the accompanying drawings. As Figure 1 shown, it is an Internet of Things transmission framework based on a proxy server. Denote the client - user as s, the proxy server as d, and the client - device as o. The following will separately describe Figures 1-3 the steps included as follows:

[0055] Step 1. Initialize user s, proxy server d, and client o:

[0056] Step 11. Use the public Hughes key exchange algorithm to calculate the shared keys K - do1 and K - do2 between proxy server d and client o;

[0057] Step 12. Evaluate each security element of customer o, including: T(o), o-s-limit(), o-s-ins-limit(), cert(o), where the certificate content includes its own ID, etc.

[0058] Step 13. Evaluate each security element of user s, including: T(s), s-o-limit(), s-o-ins-limit(), cert(s), where the certificate content includes its own ID, etc.

[0059] The present invention does not specifically discuss the access control method between the user and the proxy server here. Only the security access control method between the proxy server d and the customer o is involved below, and the relevant information of the user s will be used in the later process.

[0060] Step 2. The proxy server d subscribes to the instruction {$s-o} from the customer o, as shown in Figure 2 the left part.

[0061] The proxy server d subscribes to the instruction from the customer o and uses the aforementioned improved splitting idea for data transfer.

[0062] Step 21. The proxy server d encrypts the instruction {$s-o} subscribed to the customer o using the LBlock algorithm to form E K-do1 {$s-o}.

[0063] Step 22. The proxy server d selects a random number R and concatenates E K-do1 {$s-o}, the instruction {$s-o} subscribed by the proxy server d to the customer o, and the timestamp t3 of the instruction subscribed by the proxy server d to the client o together: E K-do1 ({$s-o})||cert(d)||t3||({$s-o})) is denoted as M. Compare the number of bits of M, R, and K-do2 (the shared key 2 between d and o). If the lengths are different, pad the front of the party or both parties with fewer bits with several 0s to make the number of bits of the three consistent;

[0064] Step 23. Calculate (E K-do1 ({$s-o})||cert(d)||t3||({$s-o}))⊕R and R⊕K-do2 and send them to the customer o at the same time.

[0065] Here, it is mainly considered that most customers o are lightweight; no complex operations are used. Only the random number R generated by the proxy server d, and the shared keys K-do1 and K-do2 known to the proxy server d and the customer o are used for encryption and exclusive OR to ensure information confidentiality; use E K-do1 ({$s-o}) and cert(d) to ensure that the information source is reliable and comes from the proxy server d;

[0066] Step 3. Customer o receives the information from proxy server d and processes it, as shown in Figure 2 the right part;

[0067] Step 31. Record the timestamp when customer o receives the data sent by proxy server d as t4;

[0068] Step 32. According to the received result {E K-do1 ({$s - o})||cert(d)||t3||({$s - o}))⊕R, R⊕K - do2, calculate: {E K-do1 ({$s - o})||cert(d)||t3||({$s - o}))⊕R}⊕{R⊕K - do2}⊕K - do2; Restore (E K-do1 ({$s - o})||cert(d)||t3||({$s - o}));

[0069] Step 33. According to the result restored in Step 32, judge the time: If t4 > t3 + Δt, the access is interrupted;

[0070] Step 34. According to the result restored in Step 32, use the E K-do1 ($s - o) algorithm with the key K - do1 to decrypt D K-do1 (E K-do1 ({$s - o})) to obtain $s - o;

[0071] Step 35. Compare the result $s - o in Step 34 with the $s - o in the result of Step 32. If they are inconsistent, the access is interrupted;

[0072] Step 36. According to cert(d) in the result restored in Step 32, and the shared keys K - do1 and K - do2 between proxy server d and customer o, confirm whether the information comes from d; If not, the access is interrupted; After Steps 35 and 36, it can be confirmed whether the information is complete;

[0073] Step 4. Customer o publishes the subscription data $o - s according to the content of $s - o, as shown in Figure 3 the left part.

[0074] Customer o publishes the subscription data to proxy server d and uses the aforementioned improved splitting idea for data transfer.

[0075] Step 41. Customer o generates the subscription data $o - s according to the content of $s - o;

[0076] Step 42. Generate the subscription instruction and the security instruction set {$o - s, SE - o}, where SE - o = {cert(o), T(o), o - s - limit(), o - s - ins - limit()};

[0077] Step 43. Encrypt using the LBlock algorithm, with the key being K-do2 to encrypt $o-s||cert(o)$, obtaining E K-do2 ($o-s||cert(o));

[0078] Step 44. Customer o selects a random number R1, concatenates the results of steps 42 and 43 { $o-s, SE-o}||E k3 ($o-s||cert(o))||t5 (t5 is the timestamp when o issues the data $o-s instruction), denoted as Q. Compare Q, R1 with the number of digits of K-do. If the lengths are different, pad the front of the one with fewer digits with several 0s to make the three have the same number of digits;

[0079] Step 45. Calculate ({ $o-s, SE-o}||E K-do2 ($o-s||cert(o))||t5) ⊕ R1 and R1 ⊕ K-do1 (XOR calculation) respectively;

[0080] Step 46. Send to proxy server d simultaneously;

[0081] Step 5. After proxy server d receives the information from customer o, judge the information source and reliability, such as Figure 3 the right part.

[0082] Step 51. Record the timestamp when proxy server d receives the data sent by customer o, denoted as t6;

[0083] Step 52. Use K-do1 to perform XOR calculation on the result received from customer o, calculate {({ $o-s, SE-o}||E K-do2 ($o-s||cert(o))||t5) ⊕ R1} ⊕ {R1 ⊕ K-do1} ⊕ K-do1 to obtain { $o-s, SE-o}||E k-do2 ($o-s||cert(o))||t5;

[0084] Step 53. According to the time information obtained in step 52, judge the timestamp: If t6 > t5 + Δt, the access is interrupted;

[0085] Step 54. According to step 52E k-do2 ($o-s||cert(o)), decrypt D K-do2 (E k-do2 ($o-s||cert(o))) to obtain: $o-s||cert(o);

[0086] Step 55. According to cert(o) in the security element set SE-o of customer o obtained in step 52, and cert(o) in step 54, the identity is authentic, the message comes from o, ensuring the reliability of the information source; if it is unreliable, the access is interrupted.

[0087] Step 56. Compare $o-s obtained in step 52 with $o-s in step 54 to determine whether the content is consistent, ensuring the integrity of the information; if they are inconsistent, the access is interrupted.

[0088] Step 57. Initialize the result according to steps 42 and 13, check the security parameter sets of user s and customer o (where the relevant security parameters of user s are transmitted to proxy server d through the previous data transmission link from user s to proxy server d. The specific secure transmission process is not discussed in this invention and is omitted), check the publishing instruction and the content of the published data, and perform the following operations:

[0089] Step 571. Use T(s) and T(o) for comparison. If the security levels of the two do not satisfy T(s)≥T(o), the security level is insufficient and the access is interrupted (since there was no security element set of customer o stored in the proxy server before, only after waiting for customer o to transmit information to proxy server d can it be judged).

[0090] Step 572. Determine whether user s is a restricted user of customer o. If s∈o-s-limit(), the access is interrupted.

[0091] Step 573. Determine whether the instruction $s-o issued by user s is within the content of the set of instruction keywords that customer o does not allow user s to publish. If $s-o∈o-s-ins-limit(), the access is interrupted.

[0092] Step 574. Determine whether customer o is in the set of blacklisted devices of user s. If o∈s-o-limit(), the access is interrupted.

[0093] Step 575. Determine whether the subscription data published by customer o is within the subscription data that user s does not allow customer o to publish. If $o-s∈s-o-ins-limit(), the access is interrupted.

[0094] After the above operations, the $o-s received by proxy server d is secure data that meets the subscription instruction conditions, has a reliable information source, no leakage of secrets, and complete information.

[0095] Those of ordinary skill in the art will realize that the embodiments described herein are provided to assist the reader in understanding the principles of the present invention, and it should be understood that the scope of protection of the present invention is not limited to such specific statements and embodiments. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. A method for secure access control of IoT devices based on segmentation, characterized in that: The application scenario includes: client, proxy server, user; the client is denoted as o, the proxy server is denoted as d, and the user is denoted as s; the access control method includes the following steps: S1, proxy server d generates a subscription instruction according to the instruction sent by user s, and uses the improved segmentation method to send the subscription instruction to client o; the shared keys of proxy server d and client o are recorded as K-do1 and K-do2; The implementation process of the proxy server d using the improved segmentation method to send a subscription instruction to the client o in step S1 includes the following steps: A1. The proxy server d encrypts the subscription instruction {$so} sent to the client o using the LBlock algorithm to form E K-do1 {$so}; A2. E K-do1 {$so}, proxy server d subscribes to client o {$so}, timestamp t3 of proxy server d subscribes to client o, strung together: E K-do1 ({$so})|| cert(d)||t3||({$so})) is denoted as M. The proxy server d selects a random number R, and compares the digits of M, R and K-do2. If the lengths are different, the longest digit is used as the standard, and the remaining digits are padded with 0 to make the digits of the three digits consistent. cert(d) is the certificate of the proxy server d. A3. Calculate (E K-do1 ({$so})|| cert(d) ||t3||({$so}))⊕R 、R⊕K-do2, and send the calculation results to client o at the same time; ⊕ is the XOR symbol; S2, client o receives the information from proxy server d, processes it, and confirms the integrity of the information; S3, client o publishes subscription data to proxy server d using the improved segmentation method according to the content of the subscription instruction; the implementation process of client o publishing subscription data to proxy server d using the improved segmentation method in step S3 includes the following steps: B1. Customer o generates subscription data $os based on the content of {$so}; B2. Generate subscription instructions and security instruction set {$os, SE-o}, where SE-o = {cert(o), T(o), os-limit(), os-ins-limit()}; cert(o) is the certificate that client o applied for from proxy server d, T(o) is the security level of client o, os-limit() is the set of users that client o is restricted from accessing, and os-ins-limit() is the set of instruction keywords that client o is not allowed to subscribe to; B3. Use the LBlock algorithm to encrypt $os|| cert(o) with the key K-do2, and get E K-do2 ($os|| cert(o)); B4. Client o selects a random number R1 and concatenates the results of steps B2 and B3 together {$os,SE-o}|| E K-do2 ($os||cert(o))||t5, denoted as Q, compare the number of bits of Q, R1 and K-do1. If the lengths are different, the data with the longest number of bits shall prevail, and the remaining data shall be padded with 0 to make the number of bits of the three consistent; t5 is the timestamp when client o issues the data $os instruction; B5. Calculate ({$os,SE-o}|| E K-do2 ($os|| cert(o))||t5)⊕R1, R1⊕K-do1; and send the calculation results to the proxy server d at the same time; S4. After receiving the information from client o, proxy server d sends the information that has passed the information security and information source reliability judgment to user s.

2. According to claim 1, a method for secure access control of IoT devices based on segmentation concept is characterized in that: In step S2, customer o receives the result { E K-do1 ({$so})|| cert(d) ||t3|| ({$so})) ⊕R, R⊕K-do2, calculation: { E K-do1 ({$so})|| cert(d) ||t3|| ({$so}))⊕R}⊕{R⊕K-do2}⊕K-do2; restore (E K-do1 ({$so})|| cert(d) ||t3|| ({$so})).

3. According to claim 2, a method for secure access control of IoT devices based on segmentation concept is characterized in that: The process of confirming the integrity of information in step S2 is as follows: According to the recovered result, decrypt D with key K-do1 K-do1 (E K-do1 ({$so})) get {$so}; The decrypted {$so} is compared with the {$so} in the restored result. If they are consistent, it means that the information received by client o is complete, and then step S3 is executed; otherwise, the access is interrupted.

4. According to claim 3, a method for secure access control of IoT devices based on segmentation concept is characterized in that: The process of determining the reliability of the information source in step S4 includes the following steps: C1. XOR the result received from client o with K-do1, and calculate {({$os,SE-o}|| E K-do2 ($os|| cert(o))||t5)⊕R1}⊕{R1⊕K-do1}⊕K-do1 gets {$os,SE-o}|| E k-do2 ($os|| cert(o))||t5; C2. E obtained according to step C1 k-do2 ($os|| cert(o)), decrypt D K-do2 (E k-do2 ($os|| cert(o))) gets: $os|| cert(o); C3. Perform identity authentication based on the cert(o) in the security element set SE-o obtained in step C1 and the cert(o) decrypted in step C2. If the identity is authentic, the source of the message is reliable; otherwise, access is interrupted.

5. According to claim 4, a method for secure access control of IoT devices based on segmentation concept is characterized in that: The determination of information security in step S4 includes the following: Compare the $os obtained in step C1 with the $os in step C2. If the contents are consistent, the information is complete. Otherwise, the access is interrupted; Check the security parameter set of user s and client o in the proxy server d, including: security level judgment, access restriction judgment, and sensitive character judgment; The security level is judged as follows: if T(s) ≥ T(o), the security level is considered to meet the requirements, otherwise the access is interrupted, and T(s) is the security level of user s; The specific judgment of restricted access is: if s∈os-limit(), user s is a restricted user of customer o, and the access is interrupted, otherwise the access is normal; if o∈so-limit(), customer o is a restricted user of user s, and the access is interrupted, otherwise the access is normal; The specific judgment of sensitive characters is as follows: if $so∈os-ins-limit(), the instruction $so published by user s is the instruction keyword set content that customer o is not allowed to subscribe to, and the access is interrupted, otherwise the access is normal; if $os∈so-ins-limit(), the subscription data published by customer o is the release data keyword set content that user s is not allowed to accept, and the access is interrupted, otherwise the access is normal.

Citation Information

Patent Citations

  • Method for achieving lightweight authentication and key agreement

    CN103560879A

  • Self-adaptive password authentication method and device, storage medium and electronic equipment

    CN116647402A